The easy way is to push the internal LAN route in the OpenVPN server config (push “route 192.168.3.0.255.255.255.0” in this case).

The more secure way is NOT to push the route in the OpenVPN server config, but instead push only the relevant allowed destinations in the OpenVPN ccd/client file like push “route 192.168.3.200”, but in this case the “Employees Class” from the example wouldn't work, cause there is no file to include the routing.

Examples

OpenVPN Server Config

Note: It is very important that Topology “Use Default” is used and NOT “Subnet”!